CVE-2021-31401
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue was discovered in tcp_rcv() in nptcp.c in HCC embedded InterNiche 4.0.1. The TCP header processing code doesn't sanitize the value of the IP total length field (header length + data length). With a crafted IP packet, an integer overflow occurs whenever the value of the IP data length is calculated by subtracting the length of the header from the total length of the IP packet.
Se ha detectado un problema en la función tcp_rcv() en el archivo nptcp.c en HCC embedded InterNiche versión 4.0.1. El código de procesamiento del encabezado TCP no sanea el valor del campo de longitud total de IP (longitud del encabezado + longitud de los datos). Con un paquete IP diseñado, se produce un desbordamiento de enteros cuando el valor de la longitud de datos IP se calcula restando la longitud del encabezado de la longitud total del paquete IP.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-04-15 CVE Reserved
- 2021-08-19 CVE Published
- 2024-08-03 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://cert-portal.siemens.com/productcert/pdf/ssa-789208.pdf | Mitigation |
|
https://www.forescout.com/blog/new-critical-operational-technology-vulnerabilities-found-on-nichestack | Mitigation | |
https://www.kb.cert.org/vuls/id/608209 | Third Party Advisory |
|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Siemens Search vendor "Siemens" | Sentron 3wl Com35 Firmware Search vendor "Siemens" for product "Sentron 3wl Com35 Firmware" | < 1.2.0 Search vendor "Siemens" for product "Sentron 3wl Com35 Firmware" and version " < 1.2.0" | - |
Affected
| in | Siemens Search vendor "Siemens" | Sentron 3wl Com35 Search vendor "Siemens" for product "Sentron 3wl Com35" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Sentron 3wa Com190 Firmware Search vendor "Siemens" for product "Sentron 3wa Com190 Firmware" | < 2.0.0 Search vendor "Siemens" for product "Sentron 3wa Com190 Firmware" and version " < 2.0.0" | - |
Affected
| in | Siemens Search vendor "Siemens" | Sentron 3wa Com190 Search vendor "Siemens" for product "Sentron 3wa Com190" | - | - |
Safe
|
Hcc-embedded Search vendor "Hcc-embedded" | Nichestack Search vendor "Hcc-embedded" for product "Nichestack" | < 4.3 Search vendor "Hcc-embedded" for product "Nichestack" and version " < 4.3" | - |
Affected
|